home.social

#industrialsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #industrialsecurity, aggregated by home.social.

fetched live
  1. Critical cybersecurity incidents continued to grow during 2025, especially in the industrial and food sectors.

    Recent reports show the most affected industries were:
    • IT → 23%
    • Government → 18%
    • Industrial → 18%

    Protecting infrastructure today requires continuous visibility, rapid detection, and expert response capabilities.

    relianoid.com/blog/critical-cy

  2. I hate digging through PCAPs, especially in OT/ICS environments, so I built a small offline tool that turns passive traffic captures into a triage report.

    New blog post: Turning OT PCAP Pain into a Triage Report

    0ut3r.space/2026/05/08/ot-pcap

    Enjoy or not.

    #OT #ICS #SCADA #PCAP #Wireshark #tshark #CyberSecurity #IndustrialSecurity #Python #OpenSource

  3. Gianluca Caiazza (orcid.org/0000-0002-2820-7121) has joined the ACP section! He will serve as Assistant Professor at the new campus in Vejle. His field of expertise is industrial network edge cybersecurity.

    #cybersecurity #infosec #security #industrialSecurity #edgeSecurity

  4. 🔴 Wake-up call for critical infrastructure security:

    CERT Polska’s recent report on an energy sector cyber incident is a stark reminder that modern attacks on critical infrastructure are no longer just about data — it's about disruption and destruction.

    cert.pl/uploads/docs/CERT_Pols

    #OTSecurity #ICS #CriticalInfrastructure #CyberResilience #IndustrialSecurity

  5. Bald ist wieder #itsa. Anfang Oktober trifft man sich wie in jedem Jahr in #Nürnberg auf dem Messegelände, um sich zum Thema #Security auszutauschen.

    #FORTINET ist natürlich mit dabei, inklusive einer Ausstellung unserer wunderschönen Ruggedized-Gerätelandschaft.

    Ich bin nicht die ganze Woche vor Ort, vermutlich nur am ersten Tag, also wer mal hallo sagen möchte, komm Dienstags vorbei. ;-)

    Noch kein Ticket? Dann gerne hier entlang: events.fortinet.com/it-sa2025

    #OT #IndustrialSecurity #KRITIS

  6. 🔐 Practical Industrial Security: Real-World Lessons from Complex HVDC Projects

    We’re excited to announce that our colleague Jan Grotelüschen (GAI NetConsult GmbH) will be speaking at the Industrial Security Conference 2025 in Copenhagen, alongside Simon Gustafson (Amprion GmbH) and co-author Stephan Beirer (GAI NetConsult GmbH).

    🎤 Topic of the presentation:
    Staying on course in a volatile environment: OT security in complex large-scale HVDC projects – a real-life example

    insightevents.dk/isc-cph/sessi

    ⚡ At a glance:

    Amprion is currently implementing massive offshore grid connection projects such as BorWin4/DolWin4 and BalWin1/BalWin2. These high-voltage direct current (HVDC) lines span up to 380 km and deliver 5.8 GW of power per project – enough to supply electricity to nearly 6 million people.
    In this presentation, the speakers, who are largely responsible for the specification and monitoring of the implementation of OT security for this HVDC project, will present the projects itself and report on the cyber security challenges and lessons learnt.

    🔍 Key OT Security Challenges Covered:
    • Dynamic regulation: Adapting to evolving frameworks like NIS-2, RCE, CRA – even mid-project
    • Technology vs. longevity: IT/OT convergence meets decades-long system life cycles
    • Managing uncertainty: Constant change in technologies, requirements, and stakeholders

    📌 This session provides real-world insights into securing critical infrastructure under real conditions – including what worked, what didn’t, and how lessons learned are shaping better security strategies.

    🔗 More about the industrial security conference: linkedin.com/company/industria

    #OTSecurity #CriticalInfrastructure #HVDC #CyberSecurity #EnergyTransition #ICSCPH #GAINetConsult #Amprion #NIS2 #CRA #IndustrialSecurity

  7. Ein großes Dankeschön an alle, die vorbeigeschaut, mitdiskutiert und mit uns in die digitale Zukunft geblickt haben. Genau dieser Austausch macht die Hannover Messe für uns jedes Jahr zu etwas Besonderem.

    #HM25 #6G #CyberSecurity #IntelliEdge #IndustrialSecurity #Innovation #DigitaleZukunft #MachineLearning #VirtualReality #QuantumComputing

  8. The best ICS testing results don’t come from a single approach. Onsite testing has to be risk-averse, and lab testing can uncover deeper vulnerabilities. The key? A combined approach…
     
    OT environments don't stand up to regular IT pen testing. Any pen tester that doesn't fully understand that could easily destroy systems and take out critical infrastructure.
     
    By strategically selecting devices for lab testing based on onsite insights, you get the best of both worlds without unnecessary risk or cost.
     
    In our latest blog, Head of Hardware Andrew Tierney explains how this method finds hidden threats in ICS networks: pentestpartners.com/security-b

    #cybersecurity #icsmonitoring #industrialsecurity #cyberdefense #securityresearch #operationaltechnology #incidentresponse #cyberawareness

  9. 🚨 90% of UK industrial firms hit by cyberattacks this year

    IoT vulnerabilities, insider threats, and OT risks are exposing critical systems in manufacturing, energy, and more.

    💡 How to stay secure? RELIANOID ADC protects industrial IT infrastructure with:
    ✅ mTLS authentication
    ✅ Real-time threat blocking
    ✅ Zero-downtime updates

    Strengthen your defenses today!


    relianoid.com/blog/strengtheni

  10. “Unrecognized Device in OT Environment” → Enable this rule, and you’ll get notified as soon as a new device speaks to the network.

    Then, investigate with the metadata and context gathered by our Continuous Inventory.

    Learn more at: safetybits.io/products/otspm-p #Cybersecurity #Inventory #DigitalTransformation #OTSPM #IndustrialSecurity

  11. Our inventory and network detections work together.

    Network insights complete the inventory, registering new devices as soon as they speak to the network, and security events as they happen.

    Context is already correlated for you when you need it, speeding up your forensic investigations.

    Learn more at: safetybits.io/products/otspm-p

    #Cybersecurity #Inventory #DigitalTranformation #OTSPM #IndustrialSecurity

  12. Our Continuous Inventory supports a wide catalog of brands and devices. This allows us to be proactive, providing extra information and actionable security insights.

    For example, we’ll gather for you a list of devices needing firmware updates, or that are using default credentials.

    Learn more at: safetybits.io/products/otspm-p

    #Cybersecurity #Inventory #DigitalTranformation #OTSPM #IndustrialSecurity

  13. Our Continuous Inventory tracks the changes of your devices over time.

    When you are investigating a suspicious device, you can check when it was added to the network.

    Or, if something is misbehaving, you can check when a configuration change took place.

    Learn more at: safetybits.io/products/otspm-p

    #Cybersecurity #Inventory #DigitalTranformation #OTSPM #IndustrialSecurity

  14. Oohh look what I found on my desk this morning! Hot off the press, the 3rd edition. 👍

    I don't usually get excited about books, but this is to industrial security what "The C Programming Language" is to devs. The definitive guide to the subject. Best read slowly and with copious notes scribbled down.

  15. Microsoft identifies 15 high severity vulnerabilities in affected PLCs running CODESYS software. If successfully exploited, attackers could cause widespread damage including shutting down power plants.

    Fortunately, attacks of these nature are rare & the vulnerabilities are difficult to exploit. Nevertheless, both CODESYS & Microsoft recommends organizations running affected devices should patch the PLCs.

    https://arstechnica.com/security/2023/08/microsoft-finds-vulnerabilities-it-says-could-be-used-to-shut-down-power-plants/

    #infosec #cybersecurity #industrialsecurity #PLC #CODESYS #Microsoft

  16. Checkout the most identified present and missing controls over the years within industrial environments.

    securiacs.com/industrial-secur

  17. For those in the #industrialsecurity world and watching for new advisories, #CISA released four Industrial Control Systems Advisories:
    - ICSA-23-017-01 GE Proficy Historian
    - ICSA-23-017-02 Mitsubishi Electric MELSEC iQ-F, iQ-R Series
    - ICSA-23-017-03 Siemens SINEC INS
    - ICSA-22-347-03 Contec CONPROSYS HMI System (CHS) (Update A)

    cisa.gov/uscert/ncas/current-a | #CriticalInfrastucture

  18. Die US-Behörde CISA hat am 10. November 2022 einen 3 Punkteplan für effizientes Schwachstellenmanagement veröffentlicht: cisa.gov/blog/2022/11/10/trans

    Zentrale Punkte sind der #CSAF-Standard und das #VEX-Profil: Maschinenlesbare #Advisory reduzieren den manuellen Aufwand und mitigieren effektiver Schwachstellen.

    Die #CISA zeigt hiermit offiziell ihre Unterstützung dieses Standards. Das #BSI erwartet eine Signalwirkung für alle PSIRTs – speziell auch #IndustrialSecurity.

    #DeutschlandDigitalSicherBSI

  19. Das Common Security #Advisory Framework (#CSAF) liefert maschinenverarbeitbare Advisories

    Gemeinsam mit dem Cyber-Defense Campus (CYD Campus) in der Schweiz arbeitet das #BSI daran #OpenSource-#Tools bereitzustellen, damit alle Beteiligten einer Supply-Chain CSAF-Advisories erzeugen und verwalten können, um effizienter Schwachstellen-Informationen auszutauschen und ihre IT-Sicherheit zu verbessern.
    👉 admin.ch/gov/de/start/dokument

    #IndustrialSecurity #Secvisogram #DeutschlandDigitalSicherBSI

  20. Das #BSI hat eine Studie zum Status Quo der „Safety & Security“ in störfallrelevanten Betriebsbereichen von Industrieanlagen veröffentlicht.

    Die Studie zeigt, welche Herausforderungen die Cybersicherheit für den Betrieb solcher Anlagen mit sich bringt und zeigt Lösungswege auf. Deren hohe Bedeutung wird auch durch die neuen Meldepflichten der Anlagenverantwortlichen aus dem IT-Sicherheitsgesetz 2.0 deutlich.
    👉 bsi.bund.de/SharedDocs/Downloa

    #IndustrialSecurity #DeutschlandDigitalSicherBSI

  21. Industrielle Steuerungs- und Automatisierungssysteme (Industrial Control Systems, ICS) haben lange Lebenszeiten und sind einem großen Risiko ausgesetzt, wenn sie über ihr Support-Ende hinaus betrieben werden und somit keine sicherheitsrelevanten Updates mehr erhalten.
    Eine im Oktober 2021 erschienene Cyber-Sicherheitsempfehlung des #BSI gibt einen Überblick über diesbezügliche Herausforderungen und Maßnahmen.
    👉 allianz-fuer-cybersicherheit.d

    #IndustrialSecurity #DeutschlandDigitalSicherBSI